securityonline.info 23 Sept 2026, 02:56 UTC

IBM Patches 22 DataStage Flaws Enabling Command Execution and Credential Theft

IBM Patches 22 DataStage Flaws Enabling Command Execution and Credential Theft

IBM has disclosed 22 vulnerabilities affecting DataStage on Cloud Pak for Data 5.4.0.0. The supplied report identifies eight CVEs, including CVE-2026-16346, rated 9.9 on CVSS v3, and says the wider set includes one critical and seven high-severity flaws. The issues could allow authenticated remote attackers to execute arbitrary commands, cause denial of service, access files or intercept credentials. No active exploitation or public proof-of-concept exploits has been confirmed.

The reported weaknesses include OS command injection, path traversal during archive extraction and TLS certificate validation problems. CVE-2026-17102 and CVE-2026-81545 allegedly allow attackers to inject commands, while CVE-2026-84421 could enable access to or overwriting of restricted files.

The report also describes a cross-tenant credential exposure issue, in which a shared, unrotated master key could allow an authenticated user to recover other tenants’ connection passwords, Git personal access tokens and IAM API keys. It further says CVE-2026-84418 could let an attacker use a forged certificate to capture an IAM bearer authorisation header.

IBM recommends upgrading DataStage on Cloud Pak for Data to version 5.4 patch 7 or later, following its official upgrade instructions. The report presents this as the remediation for all 22 vulnerabilities and urges administrators not to delay, despite there being no confirmed exploitation.

View full article

Article by CyberSIXT